Sitelet https://web.archive.org/web/20231219003703/https://github.com/github/codeql/pull/15039
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

C#: Add flow steps from a PageModel to cshtml page. #15039

Open
wants to merge 4 commits into
base: main
Choose a base branch
from

Conversation

joefarebrother
Copy link
Contributor

@joefarebrother joefarebrother commented Dec 7, 2023 •

Adds flow steps from PageModel handler methods (calls to PageModel.Page() and PageModel.RedirectToPage() as well as implicit flow from this in void-returning handler methods) to the Model field in the code generated from the .cshtml file for the corresponding page.

@github-actions github-actions bot added the C# label Dec 7, 2023
@joefarebrother joefarebrother marked this pull request as ready for review December 12, 2023 16:54
@joefarebrother joefarebrother requested a review from a team as a code owner December 12, 2023 16:54
Copy link
Contributor

@tamasvajk tamasvajk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't know enough about razor pages, but this looks plausible to me. I added one minor comment.

Let's wait for others to review it before merging.

/** Gets a handler method such as `OnGetAsync` */
Method getAHandlerMethod() {
result = this.getAMethod() and
result.getName().matches("On%") and
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should OnPageHandler% methods be filtered out?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hmm, I guess those methods are not technically handler methods; however they are called during the page handler process, so it makes sense to consider tainted writes to the model in those methods to still propagate to the page.


from DataFlow::Node source, DataFlow::Node sink
where TestXss::flow(source, sink)
select sink, source, sink, "Xss"
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I suggest making this a path-problem query instead.

private MethodCall getImplicitThisCallInVoidHandler(PageModelClass pm) {
result.getEnclosingCallable() = pm.getAHandlerMethod() and
result.getEnclosingCallable().getReturnType() instanceof VoidType and
result.hasImplicitThisQualifier()
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why only implicit this qualifiers?

PageModelClass pm;

PageModelJumpNode() {
this.asExpr() = [getAPageCall(pm), getImplicitThisCallInVoidHandler(pm)].getQualifier()
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For the getImplicitThisCallInVoidHandler case, I would expect that the node should be the post-update node, as that is what is that target of stores. I.e., in this.Name = source() the store is into the post-update node for this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants